ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] Shaw Secure, F-Secure calling home

From: "Jason" <jalhab1@xxxxxxx>
Date: Fri, 6 Nov 2009 13:49:00 -0700

Hello all,

 

I use Shaw Secure which is basically F-secure with Shaw Ad's..

shawsecure.ca/

www.f-secure.com/en_US/

I also run Protowall in the background on my PC.

en.wikipedia.org/wiki/ProtoWall

Whenever Protowall is on sure enough these lines always pop up constantly..

Packet to "Media Force, MCI Communications Services, Inc. d..." (
65.200.212.211 ) blocked. [protocol: TCP - src: 1205 / dst: 80]

Packet from "Media Force, MCI Communications Services, Inc. d..." (
65.200.212.213 ) rejected. [protocol: TCP - src: 80 / dst: 1224]

These packets will be blocked or rejected sometimes up to 100 times an hour 24/7. A heck of a lot anyway.

I looked it up and I think its F-secure's servers. Automatic updates are OFF. So why does it keep calling out and what is it sending/receiving?

Is anyone else using Shaw/F-Secure? Can anyone smarter than me in these areas shed some light? There are alot of people that use Shaw Secure and F-Secure. I have installed Wireshark but it’s gibberish to me so far. If someone can tell me what is being sent/received please?

 

Thanks